ThreatHalo is built by Chorus Cyber. Chorus Cyber is committed to protecting your personal information and being transparent about what information we hold.
The purpose of this Privacy Policy (‘Policy’) is to give you a clear explanation about how Chorus collects and uses the personal information (or personal data) you provide to us and what we collect, whether online, via phone, email, in letters or in any other correspondence or from third parties.
Chorus will hold the minimum personal information necessary to enable it to perform its functions.
We ensure that we use your personal information in accordance with the law. This Policy explains:
This policy is part of the wider security policies of Chorus which covers Information Security and data management.
If you have any queries about this privacy and cookies policy, please contact the Data Protection Officer at Chorus Global Holdings Limited, 1 Serbert Way, Bristol, BS20 7GD or email: GDPR@chorus.co.uk
The Policy may change from time to time to reflect changes in the law or our practices. Please visit this website section periodically in order to keep up to date with the changes in our Policy.
We currently collect and process the following information:
Cookies
A cookie is a small file stored on your device when you visit our websites. These enable us to customise your experience on the sites, storing preferences to make future visits smoother. The cookies and cookie providers we use are dependent on the website you are accessing and further details can be found following the links to the relevant cookie policies within the web page.
We use the following categories:
Non-essential cookies are only active once you have given consent via our cookie banner. You can withdraw consent at any time via your browser settings or by following the links on the webpage.
A full list of cookies in use, including name, duration and provider, is available by following the cookie policy link on the specific website.
Information Collected Automatically Through the Website
When you visit our websites we automatically collect:
This is collected via server logs and analytics tools and is used to operate, secure and improve the website, and — where you have consented — for analytics and marketing measurement as set out above.
Most of the personal information we process is provided to us directly by you for one of the following reasons:
If you apply to work at Chorus, we will only use the information you give us to process your application or to monitor recruitment statistics on an unidentified basis. If we want to disclose information to someone outside of Chorus, we will tell you beforehand. The only exception is where the law obliges us to disclose information to a third party (such as the police) and we are not allowed to tell you.
We may also contact references provided by yourself as part of the recruitment process. However, this is only done once an offer of employment has been made and accepted.
If you are unsuccessful in your job application, we may hold your personal information after we’ve finished recruiting for the post you applied for, if you do not wish for this information to be retained please contact HRadmin@chorus.co.uk and we will arrange for the records to be deleted.
We keep statistical information about all applicants to develop our recruitment processes however no individual applicant would be identifiable from this information.
If you commence employment with Chorus, your personal information will be processed in accordance with your employment contract and other applicable human resources policies we have from time to time.
We use your personal information for a number of purposes including the following:
Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are:
Legitimate Interest
We rely on the “legitimate interest’s” ground for processing where we believe it is in the legitimate interests of you, as the data subject, or of Chorus, to process your data. When we process your personal information in this way, we also consider and balance any potential impact on you (both positive and negative), and your rights under data protection laws.
We will not use your personal information for activities where our interests are overridden by the impact on you, for example where collection and use of your information would be excessively intrusive (unless, for instance, we are otherwise required or permitted to by law). We will only use your information in accordance with the purposes described in this Policy.
Examples of processing based on the legitimate interest’s ground are:
Consent
In many instances, we will rely on obtaining your consent to our use of your personal information in a certain way (for example, asking for your consent to use your personal information to send you direct marketing information)
Legal Obligation
We may need to collect, process and disclose personal information to comply with a legal obligation. For example, where we are ordered by a court or regulatory body.
We may also use personal information to cross check and prevent known malicious activities on Chorus operated services.
Performance of a contract
For example if you purchase our services or agree to work for us, we need to be able to process your information for the purpose of meeting our contractual obligations.
Your information is securely stored in line with our zero trust principles. We use tools such as encryption, least privilege and network monitoring to ensure the confidentiality and integrity of your data. We also undergo periodic third party penetration testing to ensure our security measures are best in class.
We keep your personal information only for as long as we need to use it for the purposes set out in this Policy.
We have adopted a data retention policy that sets out the different periods we retain personal information for in respect of these relevant purposes. The criteria we use for determining these retention periods is based on various legal requirements; the purpose for which we hold data and whether there is a legitimate reason for continuing to store it (such as in order to deal with any future legal disputes); and guidance issued by relevant regulatory authorities including, but not limited to, the Information Commissioner's Office (ICO).
Personal information that we no longer need is securely disposed of and/or anonymised so you can no longer be identified from it. Some personal information may be retained by us in archives for statistical or historical research purposes although we will do this in a manner that complies with applicable data protection law.
We continually review what personal information and records that we hold and delete what is no longer required.
Under data protection law, you have rights including:
You may opt-out of our marketing communications at any time by clicking the ‘unsubscribe’ link at the end of our marketing emails.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at GDPR@chorus.co.uk or Chorus Global Holdings Limited, 1 Serbert Way, Portishead, Bristol BS20 7GD if you wish to make a request.
To exercise any of these rights, please send a description of the personal information in question to our Data Protection Office at the address shown above. Please note that some of these rights may be subject to legal restrictions, which we'll tell you about if they apply.
For more information about your rights or if you are not happy with our response to your request, you can contact the Information Commissioner’s Office (ICO) – for more details, see ico.org.uk
Chorus engages a number of third party organisations as sub-processors to process personal data on its behalf in connection with the delivery of its services and the operation of its business. These sub-processors may include, but are not limited to, providers across the following categories of tools and services:
Customer and technical support ticketing and case management systems; cloud-based productivity, communication and collaboration platforms; telephony, call handling and call recording systems; audio and meeting transcription services; customer relationship management and account management tools; human resources, payroll and recruitment platforms; marketing automation and analytics tools; security monitoring and incident management systems; and artificial intelligence (AI) assisted tools used to support internal operational and service delivery functions.
In addition to the above, Chorus may from time to time engage further sub-processors in connection with the delivery of certain internal operational and service delivery functions. Such providers may be used to support activities including, but not limited to, data analysis, information processing, security operations, communications, and the improvement of operational efficiency across our managed services.
Where personal data is processed through any such provider, Chorus takes steps to ensure that appropriate contractual and technical safeguards are in place. Any sub-processor engaged in connection with the processing of personal data will be appointed under a Data Processing Agreement that imposes obligations equivalent to those required under applicable data protection legislation. Such providers are permitted to process personal data only in accordance with our documented instructions and for no other purpose.
Certain sub-processors used by Chorus may process data in countries outside the United Kingdom. Where international transfers of personal data take place, Chorus ensures that appropriate transfer mechanisms are in place in accordance with UK GDPR requirements, such as Standard Contractual Clauses or an International Data Transfer Agreement based on the ICO’s approved template, to ensure that personal data continues to receive an adequate level of protection irrespective of where it is processed.
We apply the principle of data minimisation in our use of third party sub-processors, and we do not permit personal data processed on our behalf to be used by sub-processors for their own purposes, including the development or training of their products and services. Data retention by such providers is limited to the minimum period necessary for the delivery of the relevant function and is governed by the terms of the applicable sub-processor agreement.
Chorus reviews its use of third party sub-processors on a periodic basis. Where any change in the sub-processors we engage materially affects the way in which personal data is processed, this policy will be updated accordingly and notification provided in line with section 2 of this policy.
If you have any concerns about our use of your personal information, you can make a complaint to us at GDPR@chorus.co.uk
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: www.ico.org.uk
Last updated: August 2026.